Back to Explore
๐Ÿ›ก๏ธ

IT & Cyber Audit

Third-Party SOC Assurance

Outsourcing moves the controls, not the accountability; ISAE 3402 / SOC reports are how you obtain assurance over them.

๐Ÿ“– 6 min read๐ŸŽฏ Intermediateโœ๏ธ Updated 2026

Why outsourced controls still belong on the audit file

When financial or HR processing is outsourced to a service provider or cloud host, the controls move but the accountability does not โ€” the accounting officer remains responsible, and the auditor must obtain assurance over the provider's control environment. An ISAE 3402 or SOC report is the standard mechanism for that assurance, and a missing or expired report leaves a control gap the AGSA cannot bridge. AuditPro Core tracks the coverage and currency of assurance reports across the entity's outsourced providers and identifies the complementary user-entity controls the entity itself must operate.

The Numbers

AuditPro Core renders this view from your tenant's live, tamper-evident records. The figures below are illustrative sample data.

Critical providers

38

Current SOC report

26

of 38

Qualified opinions

3

CUECs unactioned

19

Providers by assurance status

Providers needing attention

ProviderServiceStatus
Cloud host AHostingExpired
Payroll bureauPayroll runQualified
Print vendorBilling printNo report

Figures shown are illustrative sample data for demonstration. AuditPro Core renders these views from your own tenant's live, tamper-evident records.

Type 1 versus Type 2 reports

A Type 1 report opines on control design at a point in time; a Type 2 also tests operating effectiveness over a period. Only a Type 2 supports reliance for a financial-statement audit.

Currency and period coverage

A report must cover the entity's financial year. An expired report, or a gap period not covered, leaves part of the year without assurance and may require a bridging letter.

Complementary user-entity controls

Every SOC report lists controls the provider assumes the user entity operates. If those are ignored, the provider's clean opinion does not protect the entity at all.

Sub-service organisations

Providers often rely on further sub-providers โ€” a cloud host beneath a SaaS vendor. The assurance chain must be followed through, or whole layers of the stack go unexamined.

How AuditPro Core Bridges the Gap

  • Report inventory: each outsourced provider is tracked with its report type, period covered and expiry.
  • Currency alerts: reports that have expired or fail to cover the financial year are flagged before the audit relies on them.
  • CUEC tracking: complementary user-entity controls are captured and assigned so the entity actually operates its side of the arrangement.
  • Audit-ready export: the assurance position across all providers exports as a single schedule for the audit file.

Key Takeaways

  • Only a Type 2 report supports reliance for a financial-statement audit.
  • The report must cover the financial year โ€” watch for gap periods and expiry.
  • Complementary user-entity controls must be operated, or the clean opinion is worthless to you.
  • Follow the chain to sub-service organisations so no layer goes unexamined.

See This on Your Own Data

AuditPro Core renders this dashboard from your tenant's live, tamper-evident records โ€” every figure traceable to source.